logo

Mjag dropper: Using decoy documents to drop RATs

ID: 9f448202-6aff-5ede-a7fb-c1192be3ca92

STIX ID: report--9f448202-6aff-5ede-a7fb-c1192be3ca92

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** This report analyzes the Mjag dropper (a .NET dropper obfuscated with SmartAssembly) which delivers the Punisher RAT; it documents installation and persistence behaviors, process injection (and a noted overlay injection issue), credential-stealing and keylogging modules, USB spreading, anti-analysis checks, the hardcoded C2 and protocol delimiters, and provides IOCs (MD5, filename, download URL, C2).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.